[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 9 08:13:57 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4902a7b5 by security tracker role at 2026-08-09T07:13:50+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,4 +1,102 @@
-CVE-2026-17510
+CVE-2026-71993 (MSI Radix AXE6600 router firmware version v781521 contains a command i ...)
+	TODO: check
+CVE-2026-71992 (MSI Radix AXE6600 router firmware version v781521 contains a command i ...)
+	TODO: check
+CVE-2026-71991 (MSI Radix AXE6600 router firmware version v781521 contains a command i ...)
+	TODO: check
+CVE-2026-71990 (MSI Radix AXE6600 router firmware version v781521 contains a command i ...)
+	TODO: check
+CVE-2026-71989 (MSI Radix AXE6600 router firmware version v781521 contains a command i ...)
+	TODO: check
+CVE-2026-71988 (MSI Radix AXE6600 router firmware version v781521 contains a command i ...)
+	TODO: check
+CVE-2026-71987 (MSI Radix AXE6600 router firmware version v781521 contains a command i ...)
+	TODO: check
+CVE-2026-71986 (MSI Radix AXE6600 router firmware version v781521 contains a command i ...)
+	TODO: check
+CVE-2026-71985 (MSI Radix AXE6600 router firmware version v781521 contains a command i ...)
+	TODO: check
+CVE-2026-71984 (MSI Radix AXE6600 router firmware version v781521 contains a command i ...)
+	TODO: check
+CVE-2026-71983 (MSI Radix AXE6600 router firmware version v781521 contains a command i ...)
+	TODO: check
+CVE-2026-19341 (A security vulnerability has been detected in UTT HiPER 1200GW up to 2 ...)
+	TODO: check
+CVE-2026-19340 (A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0 ...)
+	TODO: check
+CVE-2026-19339 (A security flaw has been discovered in aliyun alibabacloud-dataworks-m ...)
+	TODO: check
+CVE-2026-19338 (A vulnerability was identified in automateyournetwork MCPyATS up to 0. ...)
+	TODO: check
+CVE-2026-19337 (A vulnerability was determined in adenot mcp-google-search up to 0.3.1 ...)
+	TODO: check
+CVE-2026-19336 (A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. Th ...)
+	TODO: check
+CVE-2026-19335 (A vulnerability has been found in Jane-xiaoer skill-vision-control up  ...)
+	TODO: check
+CVE-2026-19334 (A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a ...)
+	TODO: check
+CVE-2026-19333 (A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0 ...)
+	TODO: check
+CVE-2026-19332 (A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. A ...)
+	TODO: check
+CVE-2026-19331 (A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0. ...)
+	TODO: check
+CVE-2026-19330 (A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1. ...)
+	TODO: check
+CVE-2026-19329 (A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57c ...)
+	TODO: check
+CVE-2026-19328 (A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. ...)
+	TODO: check
+CVE-2026-19327 (A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue a ...)
+	TODO: check
+CVE-2026-19326 (A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vuln ...)
+	TODO: check
+CVE-2026-19325 (A security vulnerability has been detected in IncomeStreamSurfer roo-c ...)
+	TODO: check
+CVE-2026-19324 (A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e2 ...)
+	TODO: check
+CVE-2026-19323 (A security flaw has been discovered in azer react-analyzer-mcp up to 3 ...)
+	TODO: check
+CVE-2026-18603 (The PiWeb Cancel order / Refund request for WooCommerce WordPress plug ...)
+	TODO: check
+CVE-2026-18473 (The WP Directory Kit WordPress plugin before 1.5.5 does not properly s ...)
+	TODO: check
+CVE-2026-18465 (The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capab ...)
+	TODO: check
+CVE-2026-18464 (The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capab ...)
+	TODO: check
+CVE-2026-18357 (The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does n ...)
+	TODO: check
+CVE-2026-18037 (The Create WordPress plugin before 2.5.4 does not perform an authoriza ...)
+	TODO: check
+CVE-2026-18032 (The WP Data Access  WordPress plugin before 5.5.79 does not validate t ...)
+	TODO: check
+CVE-2026-17044 (The Iptanus File Upload WordPress plugin before 5.1.8 does not properl ...)
+	TODO: check
+CVE-2026-17017 (The CubeWP Framework WordPress plugin before 1.1.31 does not properly  ...)
+	TODO: check
+CVE-2026-17014 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not pe ...)
+	TODO: check
+CVE-2026-17011 (The Nexter Blocks  WordPress plugin before 5.0.2 does not restrict who ...)
+	TODO: check
+CVE-2026-16992 (The Create WordPress plugin before 2.5.4 does not perform an authoriza ...)
+	TODO: check
+CVE-2026-16988 (The GeoDirectory  WordPress plugin before 2.8.169 does not perform any ...)
+	TODO: check
+CVE-2026-16965 (The Solace Extra WordPress plugin before 1.6.1 does not perform capabi ...)
+	TODO: check
+CVE-2026-16957 (The Slim SEO  WordPress plugin before 4.9.11 does not restrict a post- ...)
+	TODO: check
+CVE-2026-16032 (The LWS Optimize  WordPress plugin before 4.1.2 does not properly esca ...)
+	TODO: check
+CVE-2026-15038 (The InfiniteWP Client WordPress plugin before 1.13.6 does not properly ...)
+	TODO: check
+CVE-2026-11612
+	REJECTED
+CVE-2026-10595 (A path traversal vulnerability exists in parisneo/lollms version 2.1.0 ...)
+	TODO: check
+CVE-2026-17510 (Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL poin ...)
 	- libcrypt-openssl-pkcs12-perl <unfixed> (bug #1143970)
 	[trixie] - libcrypt-openssl-pkcs12-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42524422/
@@ -1056,126 +1154,167 @@ CVE-2026-64638 (WordPress is vulnerable to a pre-auth reflected XSS vulnerabilit
 	NOTE: https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
 	NOTE: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf
 CVE-2026-19137 (Use after free in WebGL in Google Chrome on Android prior to 151.0.792 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19149 (Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.1 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19154 (Use after free in Skia in Google Chrome on Android prior to 151.0.7922 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19157 (Out of bounds write in ANGLE in Google Chrome on Android prior to 151. ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19170 (Use after free in WebGL in Google Chrome on Android prior to 151.0.792 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19172 (Use after free in Views in Google Chrome prior to 151.0.7922.109 allow ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19169 (Insufficient validation of untrusted input in Contextual Tasks in Goog ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19168 (Inappropriate implementation in V8 in Google Chrome prior to 151.0.792 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19138 (Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19139 (Race in CredentialProvider in Google Chrome on Windows prior to 151.0. ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19140 (Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19141 (Use after free in Resources in Google Chrome on Android prior to 151.0 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19142 (Use after free in Views in Google Chrome prior to 151.0.7922.109 allow ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19143 (Insufficient validation of untrusted input in WebAPKs in Google Chrome ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19144 (Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowe ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19145 (Use after free in Translate in Google Chrome prior to 151.0.7922.109 a ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19146 (Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.79 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19147 (Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.1 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19148 (Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.79 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19150 (Inappropriate implementation in V8 in Google Chrome prior to 151.0.792 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19151 (Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed  ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19152 (Insufficient policy enforcement in Navigation in Google Chrome prior t ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19153 (Insufficient validation of untrusted input in Workers in Google Chrome ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19155 (Use after free in Payments in Google Chrome prior to 151.0.7922.109 al ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19156 (Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109  ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19158 (Use after free in Views in Google Chrome on Windows prior to 151.0.792 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19159 (Use after free in Views in Google Chrome prior to 151.0.7922.109 allow ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19160 (Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 all ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19161 (Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 all ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19162 (Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 all ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19163 (Use after free in Media in Google Chrome on Windows prior to 151.0.792 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19164 (Insufficient validation of untrusted input in Codecs in Google Chrome  ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19165 (Use after free in Extensions in Google Chrome prior to 151.0.7922.109  ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19166 (Use after free in Web Authentication in Google Chrome prior to 151.0.7 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19167 (Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allow ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19171 (Use after free in Media in Google Chrome on Windows prior to 151.0.792 ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19173 (Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 a ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19174 (Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowe ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19175 (Use after free in Payments in Google Chrome prior to 151.0.7922.109 al ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19176 (Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowe ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-19177 (Insufficient validation of untrusted input in UI in Google Chrome prio ...)
+	{DSA-6422-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-61478



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4902a7b59d2469c3033ea422088753caab8676aa

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4902a7b59d2469c3033ea422088753caab8676aa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260809/876215e0/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list